From 2b5113cde729e5d8059f69f6974aba5fcab2cbec Mon Sep 17 00:00:00 2001 From: sean wibisono Date: Tue, 6 Oct 2026 14:46:44 +1100 Subject: [PATCH 1/2] UID2-8027, UID2-8028: suppress 2 CVEs in .trivyignore Co-Authored-By: Claude Sonnet 5.5 --- .trivyignore | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.trivyignore b/.trivyignore index e816ccf25..c8b2d2787 100644 --- a/.trivyignore +++ b/.trivyignore @@ -105,3 +105,12 @@ CVE-2026-84370 exp:2026-10-10 # See the ticket below for the assessment. # See: UID2-8003 CVE-2026-102276 exp:2027-01-01 + +# CVE-2026-93748 — http-cache-semantics (HIGH). Required attack preconditions are absent in this +# configuration. +# See: UID2-8027 +CVE-2026-93748 exp:2027-01-06 + +# CVE-2026-85393 — node-forge (HIGH). Vulnerable code path is not reachable in this configuration. +# See: UID2-8028 +CVE-2026-85393 exp:2027-01-06 From fff59a6c6cc77076c6a12441a233f9d64accc5be Mon Sep 17 00:00:00 2001 From: sean wibisono Date: Tue, 6 Oct 2026 15:31:21 +1100 Subject: [PATCH 2/2] UID2-8026, UID2-8027, UID2-8028: suppress 3 CVEs in .trivyignore Co-Authored-By: Claude Sonnet 5.5 --- .trivyignore | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.trivyignore b/.trivyignore index c8b2d2787..522af71dd 100644 --- a/.trivyignore +++ b/.trivyignore @@ -114,3 +114,7 @@ CVE-2026-93748 exp:2027-01-06 # CVE-2026-85393 — node-forge (HIGH). Vulnerable code path is not reachable in this configuration. # See: UID2-8028 CVE-2026-85393 exp:2027-01-06 + +# CVE-2026-93687 — braces (HIGH). Required attack preconditions are absent in this configuration. +# See: UID2-8026 +CVE-2026-93687 exp:2027-01-06